7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-42052
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.

CVE-2021-43290
Software Genérico General
N/A
UNKNOWN
EPSS
3.7%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.

CVE-2021-24210
PhastPress Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
35.4%
2021 CWE-601 2 PoCs

There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another user one year ago (https://wordpress.org/support/topic/phast-php-used-for-remote-fetch/) that says that the php involved in the request only go to whitelisted pages but it's possible to redirect the victim to any domain.

CVE-2021-34427
Eclipse BIRT General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.7%
2021 CWE-20 3 PoCs

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

CVE-2021-38291
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

CVE-2021-36613
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.9%
2021 2 PoCs

Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).

CVE-2021-43454
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .

CVE-2021-25403
Samsung Account General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-200 1 PoC

Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.

CVE-2021-29263
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the project from VCS.

CVE-2021-46421
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2021 1 PoC

Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.

CVE-2021-42667
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2021 4 PoCs

A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web server and in some cases he can use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-21980
VMware vCenter Server and VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
7.5%
2021 1 PoC

The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

CVE-2021-24872
Get Custom Field Values Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-863 1 PoC

The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.

CVE-2021-26247
Cacti Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.0%
2021 CWE-79 1 PoC

As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.

CVE-2021-26807
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL loading.

CVE-2021-25765
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.

CVE-2021-37424
Software Genérico General
N/A
UNKNOWN
EPSS
13.6%
2021 1 PoC

ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

CVE-2021-29349
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails to validate the CSRF token for a POST request. An attacker can craft a module/multirecipientnotification/inbox.php pieform_delete_all_notifications request, which leads to removing all messages from a mailbox.

CVE-2021-24124
WP Shieldon Web Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-79 1 PoC

Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Unauthenticated Reflected Cross-Site Scripting (XSS) when the CAPTCHA page is shown could lead to privileged escalation.

CVE-2021-24552
Simple Events Calendar Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-89 2 PoCs

The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue